[isalist] (Newbie Alert) ISA 2004 and Citrix

  • From: "David Freeman" <dfreeman@xxxxxxxxxxxxxxxxx>
  • To: <isalist@xxxxxxxxxxxxx>
  • Date: Tue, 9 Jan 2007 10:15:16 +1000

http://www.ISAserver.org
-------------------------------------------------------

Hi All

I'm new to ISA but not particularly new to the concept of firewalls and
the like.  Previously I've used either hardware/NAT firewalls or, where
these were not appropriate, *nix-based firewalls.  For the last few
years I've been running and deploying SBS in various forms but not in 2
NIC configuration.

Over the christmas break I did a rebuild on my own SBS box (for various
reasons) and decided to add a second NIC and install ISA as part of the
rebuild.  The box is running SBS 2003 Premium with SP1.

As part of my business I need to connect to an external Citrix server
(access to a service/warranty management system for one of our
suppliers).  If I plug a computer into a network segment outside my
SBS/ISA protected network I can connect to the Citrix server just fine.
From a client inside the SBS/ISA network I do not get any errors (that I
can see) but cannot complete a connection to the citrix server.

I have created a firewall rule in ISA to permit RDP and ICA traffic
using the pre-defined protocols.  These protocols appear to agree with
the port usage information I've been able to find on the web that I
would normally use to configure a firewall rule.

I have the firewall client installed on all computers (all my internal
computers are running XP/SP2).

As noted, I'm an ISA newbie so I suspect that my problem may be as much
an understanding of ISA as a problem with firewall rules and the like.

Obviously, I have questions.

1.  Once a new rule is added and the "apply" button is clicked to commit
the changes, what else needs to be done to have client computers using
that changed configuration?

2.  What rules do I actually need to permit connections to a citrix
server from clients on my network to a server on the internet?

Any help muchly appreciated.

Thanks,
David
------------------------------------------------------
List Archives: //www.freelists.org/archives/isalist/
ISA Server Newsletter: http://www.isaserver.org/pages/newsletter.asp
ISA Server Articles and Tutorials: http://www.isaserver.org/articles_tutorials/
ISA Server Blogs: http://blogs.isaserver.org/
------------------------------------------------------
Visit TechGenix.com for more information about our other sites:
http://www.techgenix.com
------------------------------------------------------
To unsubscribe visit http://www.isaserver.org/pages/isalist.asp
Report abuse to listadmin@xxxxxxxxxxxxx

Other related posts: